Перейти к содержимому
Noroxi

Записи dotclear

32 опубликованных записей вендора dotclear.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
5
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

32 записей
  • CVE-2005-3957
    40В плане

    Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    dotclear · dotclear1 дек. 2005 г.

  • CVE-2008-3232
    38Наблюдать

    Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arb

    КритическаяCVSS 9,3Эксплойта нетEPSS 5 %

    dotclear · dotclear18 июл. 2008 г.

  • CVE-2016-7902
    36Наблюдать

    Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permi

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    dotclear · dotclear4 янв. 2017 г.

  • CVE-2015-8832
    36Наблюдать

    Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    dotclear · dotclear9 февр. 2017 г.

  • CVE-2023-53952
    34Наблюдать

    Dotclear 2.25.3 Authenticated Remote Code Execution via File Upload

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    dotclear · dotclear19 дек. 2025 г.

  • CVE-2024-58281
    34Наблюдать

    Dotclear 2.29 Remote Code Execution via Authenticated File Upload

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    dotclear · dotclear10 дек. 2025 г.

  • CVE-2011-5083
    31Наблюдать

    Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary cod

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    dotclear · dotclear19 мар. 2012 г.

  • CVE-2014-1613
    31Наблюдать

    Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-pr

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    dotclear · dotclear16 мая 2014 г.

  • CVE-2016-9268
    30Наблюдать

    Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows

    ВысокаяCVSS 7,2Эксплойта нетEPSS 5 %

    dotclear · dotclear10 нояб. 2016 г.

  • CVE-2005-3963
    30Наблюдать

    SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    dotclear · dotclear1 дек. 2005 г.

  • CVE-2011-1584
    27Наблюдать

    The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, w

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    dotclear · dotclear8 июн. 2011 г.

  • CVE-2015-8831
    25Наблюдать

    Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web scri

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    dotclear · dotclear9 февр. 2017 г.

  • CVE-2014-3781
    24Наблюдать

    The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an

    СредняяCVSS 5,8Эксплойта нетEPSS 2 %

    dotclear · dotclear11 июн. 2014 г.

  • CVE-2014-3783
    24Наблюдать

    SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories pe

    СредняяCVSS 6,0Эксплойта нетEPSS 2 %

    dotclear · dotclear22 мая 2014 г.

  • CVE-2016-6523
    24Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    dotclear · dotclear9 дек. 2016 г.

  • CVE-2014-3782
    24Наблюдать

    Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow r

    СредняяCVSS 6,0Эксплойта нетEPSS 1 %

    dotclear · dotclear11 июн. 2014 г.

  • CVE-2017-6446
    24Наблюдать

    XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    dotclear · dotclear5 мар. 2017 г.

  • CVE-2024-27626
    24Наблюдать

    A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    dotclear · dotclear20 мар. 2024 г.

  • CVE-2006-2866
    21Наблюдать

    PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP

    СредняяCVSS 5,1Proof of conceptEPSS 3 %

    dotclear · dotclear6 июн. 2006 г.

  • CVE-2006-3938
    21Наблюдать

    DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    dotclear · dotclear31 июл. 2006 г.

  • CVE-2016-9891
    21Наблюдать

    Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated use

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    dotclear · dotclear29 дек. 2016 г.

  • CVE-2018-5689
    21Наблюдать

    Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scri

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    dotclear · dotclear14 янв. 2018 г.

  • CVE-2018-5690
    21Наблюдать

    Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scr

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    dotclear · dotclear14 янв. 2018 г.

  • CVE-2018-16358
    21Наблюдать

    A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authe

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    dotclear · dotclear2 сент. 2018 г.

  • CVE-2012-1039
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML v

    СредняяCVSS 4,3Proof of conceptEPSS 4 %

    dotclear · dotclear19 мар. 2012 г.